Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer stored channel_buffers than the spec.nchannels value advertised by the rawcolor path. when oiio:rawcolor or psd:rawdata is enabled, psdinput::read_native_scanline() passes spec.nchannels to psdinput::interleave_row(), which indexes beyond channel_buffers, resulting in a heap out-of-bounds read and process crash. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::read_native_scanline(), PSDInput::interleave_row(), oiio:RawColor, psd:RawData, channel_buffers, and spec.nchannels, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read leading to process crash
Action: Patch immediately
AI Analysis

Impact

OpenImageIO can read indexed PSD files that contain transparency metadata. In versions before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1 this causes the rawcolor path to calculate a channel count that is higher than the actual buffer array. The interleave_row function then indexes beyond the bounds of channel_buffers, resulting in a heap out‑of‑bounds read and an immediate crash of the process that is performing the read. The flaw does not grant an attacker execution of code or unauthorized data disclosure; the primary impact is a denial‑of‑service through application termination.

Affected Systems

The vulnerability affects the OpenImageIO library distributed by the Academy Software Foundation. All third‑party applications or pipelines that rely on OpenImageIO to process PSD files—and use the oiio:RawColor or psd:RawData features—are susceptible when their library version is any release older than 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity. The EPSS score of < 1% signals a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves supplying a specially crafted indexed PSD file containing transparency metadata to a vulnerable host that uses OpenImageIO for image decoding. Because the flaw only causes a bounded memory read and a crash, it is not remotely exploitable for code execution but can be used to disrupt services that process user‑supplied images.

Generated by OpenCVE AI on September 19, 2026 at 18:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to at least version 3.0.21.0, 3.1.16.0, or 3.2.0.3-beta1 or newer
  • Disable or restrict usage of the oiio:RawColor and psd:RawData features for untrusted image inputs in your workflow
  • If an upgrade is not immediately possible, isolate the image decoding process in a sandboxed environment or employ operating‑system level restrictions to limit potential impact of crashes

Generated by OpenCVE AI on September 19, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer stored channel_buffers than the spec.nchannels value advertised by the rawcolor path. when oiio:rawcolor or psd:rawdata is enabled, psdinput::read_native_scanline() passes spec.nchannels to psdinput::interleave_row(), which indexes beyond channel_buffers, resulting in a heap out-of-bounds read and process crash. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::read_native_scanline(), PSDInput::interleave_row(), oiio:RawColor, psd:RawData, channel_buffers, and spec.nchannels, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Title OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row`
Weaknesses CWE-125
CWE-129
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:45:43.808Z

Reserved: 2026-07-16T19:20:28.988Z

Link: CVE-2026-63420

cve-icon Vulnrichment

Updated: 2026-09-22T14:45:39.104Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:07.837

Modified: 2026-09-29T18:56:26.687

Link: CVE-2026-63420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-129

    Improper Validation of Array Index